These v1 URLs are normative identifiers for the reference verifier. Pin the verifier release and validate the schema bytes you consume; a URL alone is not a supply-chain trust decision.
Schema set
- Subject v1 — Exact repository and revision identity.
- Policy v1 — Trusted keys, producers, controls, and freshness rules.
- Evidence v1 — Signed, scope-complete control evidence.
- Waiver v1 — Time-bounded, subject-bound exception authorization.
- Decision v1 — Deterministic fail-closed admission output.
Reference implementation
The MergeGrounds Verifier package embeds the same five files and rejects unknown fields at every security-sensitive object boundary. Read the trust-boundary guide before treating a valid document as trusted evidence.